{"id":"CVE-2026-104991","summary":"Phproject \u003c 1.8.7 Missing Authorization via Issues REST API","details":"Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API key holders to bypass the security.restrict_access confidentiality control by never invoking the allowAccess() authorization routine. Attackers can use a valid API key to read restricted issue contents and comments, including owner and author email addresses, and post unauthorized comments to issues they should not have access to.","aliases":["GHSA-mpq9-v47x-3hw8"],"modified":"2026-10-06T02:46:02.067195724Z","published":"2026-10-02T19:33:47.741Z","database_specific":{"cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104991.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/Alanaktion/phproject/releases/tag/v1.8.7"},{"type":"ADVISORY","url":"https://github.com/Alanaktion/phproject/security/advisories/GHSA-mpq9-v47x-3hw8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104991.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104991"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/phproject-missing-authorization-via-issues-rest-api"},{"type":"PACKAGE","url":"https://github.com/Alanaktion/phproject"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/alanaktion/phproject","events":[{"introduced":"910783a00c0a35a2d84265b6d32a886617d5587a"},{"fixed":"edc9e3740fde661327b7454b041e7fcc9d6a855d"}],"database_specific":{"extracted_events":[{"introduced":"1.1.6"},{"fixed":"1.8.7"},{"introduced":"0"}],"source":["AFFECTED_FIELD","DESCRIPTION","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104991.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}]}